-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Microsoft Identity and Access Administrator SC-300 Exam Guide
By :

The managed domain you choose when provisioning a tenant remains integral to the Microsoft 365 tenant throughout its entire life cycle. It functions as a fully operational domain namespace, equipped with a Microsoft-managed publicly available domain name. However, most organizations prefer to use their own domain names for activities such as email communication and Microsoft Teams interactions.
Note
Custom Domain Name System (DNS) records cannot be added to the Microsoft-managed namespace.
Organizations can add any public domain name to their Microsoft 365 tenant. Microsoft supports the configuration of up to 5,000 domains within a single tenant. This includes both top-level domains (for example, contoso.com
) and subdomains (for example, businessunit1.contoso.com
or businessunit2.contoso.com
).
Most organizations come to Microsoft 365 with existing domain names. Those domain names can easily be added to your tenant. In addition, you can purchase new domain names to be associated with your tenant.
Most large organizations have existing relationships with third-party domain registrars, such as Network Solutions or GoDaddy. You can use any ICANN-accredited registrar for your region to purchase domain names.
About ICANN
The Internet Corporation for Assigned Names and Numbers (ICANN) is a non-profit organization established in 1998 to provide guidance and policy for the internet’s unique identifiers, including domain names. Before ICANN’s formation, Network Solutions managed the global DNS registry under a subcontract from the United States Defense Information Systems Agency.
You can start your search for a domain with a registrar. A partial list of domain registrars is available here: https://www.icann.org/en/accredited-registrars.
Some organizations may wish to use Microsoft as the registrar. Depending on your subscription, you may be able to purchase domains from within the Microsoft 365 admin center, as shown in Figure 1.25:
Figure 1.25: Purchasing a domain through the Microsoft 365 admin center
When purchasing a domain through the Microsoft admin center, you may be able to purchase directly from Microsoft or may be redirected to a traditional domain registrar partner. Also, if you’ve purchased Microsoft 365 through a partner, you may be redirected to the partner’s website, depending on their relationship with Microsoft. If purchasing directly from Microsoft, you can select from the following top-level domains:
.
biz
.
com
.
info
.
me
.
mobi
.
net
.
tv
.
co.uk
.
org.uk
Domain purchases are billed separately from your Microsoft 365 subscription services. When purchasing a domain from Microsoft, you’ll have very limited ability to manage DNS records. If you require custom DNS record configuration (such as configuring a mail exchanger (MX) record to point to a third-party mail gateway), you’ll want to purchase your domains separately.
Configuring a domain for your tenant is straightforward and requires access to your organization’s public DNS service provider. Some large organizations host and manage their own DNS, while others opt to use external service providers, such as domain registrars, to provide these services.
Tip
If you’re unsure of where the DNS for your domain is hosted, you can use a service such as https://www.whois.com.
In order to be compatible with Microsoft 365, a DNS service must support configuring the following types of records:
1.2.3.4
. Later, your organization decides to develop sites for each region and you build websites for na.contoso.com
, eu.contoso.com
, and ap.contoso.com
on that same server. You might then implement a CNAME record for www.contoso.com
to point to na.contoso.com
.In order to use a custom domain (sometimes referred to as a vanity domain) with Microsoft 365, you’ll need to add it to your tenant.
To add a custom domain, follow these steps:
Figure 1.26: The Domains page of the Microsoft 365 admin center
Figure 1.27: The Add a domain page
If your domain is registered at a host that supports Domain Connect, you can click Verify and then enter your registrar’s credentials, as shown in Figure 1.28. Microsoft will automatically configure the necessary domain records on your behalf.
Figure 1.28: Authorizing Domain Connect with GoDaddy to update DNS records
You can also select More options to see all the potential verification methods available:
Figure 1.29: Completing verification records manually
If you are creating records manually, it may take anywhere from 10 minutes to 48 hours for the wizard to be able to detect the records.
autodiscover.outlook.com
.v=spf1
include:spf.protection.outlook.com -all
.Figure 1.30: Adding DNS records
_sip._tls.@<domain>
and _sipfederationtls._tcp@<domain>
.sip.<domain>
to point to sipdir.online.lync.com
and lyncdiscover.<domain>
to point to webdir.online.lync.com
.enterpriseenrollment.<domain>
to enterpriseenrollment.manage.microsoft.com
and enterpriseregistration.<domain>
to enterpriseregistration.windows.net
.selector1._domainkey
to selector1-<domain>._domainkey.<tenant.onmicrosoft.com>
and selector2._domainkey
to selector2-<domain>._domainkey.<tenant.onmicrosoft.com>
.You can continue adding as many domains as you need (up to the tenant maximum of 5,000 domains).
If you selected the DKIM option, you’ll be presented with a notification that you’ll need to go confirm the settings on the DKIM configuration page of the Microsoft 365 Defender portal (https://security.microsoft.com/dkimv2) once the DNS and service-side configuration changes have been completed.
If you attempt to enable the DKIM toggle before the configuration has been completed, you’ll receive a dialog box instructing you to make the necessary changes (see Figure 1.31).
Figure 1.31: DKIM configuration error message
If you receive this message, verify that the DNS records have been added to your DNS host.
Adding a domain deep dive
To review alternative steps (such as configuration through PowerShell) or learn more information about the overall domain configuration process, see https://learn.microsoft.com/en-us/microsoft-365/admin/setup/add-domain.
If you’ve opted to add DNS records manually, you may need to go back to the Microsoft 365 admin center and view the settings. To do this, you can navigate to the Domains page in the Microsoft 365 admin center, select your domain, and then select Manage DNS:
Figure 1.32: Managing DNS settings for a domain
On the Connect domain page, click More options to expand the options, and then select Add your own DNS records. From here, you can view the specific DNS settings necessary for each service. You can also download a file that can be uploaded to your own DNS server.
Figure 1.33: Viewing DNS settings
The CSV output is formatted as columns, while the zone file output is formatted for use with standard DNS services and can be imported into BIND or Microsoft DNS servers.
After adding a domain, Microsoft 365 automatically sets the first custom domain as the default domain, which will be selected when creating new users. However, if you have additional domains, you may choose to select a different domain to be used as the default domain when creating objects.
To manage which domain will be set as your primary domain, select the domain from the Domains page and then click Set as default to make the change:
Figure 1.34: Setting the default domain
The default domain will be selected by default when creating cloud-based users and groups. You cannot set a federated domain (for example, one that is used with Active Directory Federation Service) as the default domain.
Custom domains and synchronization
When creating new cloud-based objects, you can select from any of the domains available in your tenant. However, when synchronizing users from an on-premises directory, objects will be configured with the domain that matches the on-premises object. If the corresponding domain hasn’t been verified in the tenant, synchronized objects will be configured to use the tenant-managed domain.
Next, you will explore the core branding settings of a tenant.
Change the font size
Change margin width
Change background colour